PSD2 Final RTS: The Good, the Bad and the Ugly

Size: px
Start display at page:

Download "PSD2 Final RTS: The Good, the Bad and the Ugly"

Transcription

1 WHITEPAPER PSD2 Final RTS: The Good, the Bad and the Ugly The EBA s new final RTS on Strong Customer Authentication (SCA) and Secure Communications is an acceptable offering that seems to cover a lot of ground and will satisfy most, but ultimately leaves many unanswered questions. In a follow up to last year s Ten Key Points of the PSD2 Draft RTS, we review the final draft and re-visit our original feedback to see what s changed and what stays the same. 1. Banks to define their own interfaces GOOD. The RTS still offers no detailed standard for TPP APIs, and even avoids mentioning APIs at all. Interoperability is supposed to mysteriously emerge. Happily some industry groups (e.g. Berlin Group) have come together to define common standards, and the European Retail Payments Board (ERPB) has convened working groups to facilitate this process. It s up to the banks to define their own interfaces, but at least they will have some de-facto standards to base them on. Predictably, several organisations are springing up to offer meta-aggregation services. These act as a gateway to several banks by offering a single standard interface to Account Information Service Providers (AISPs) and Payment Initiation Service Providers (PISPs). The meta-aggregator implements all the different interfaces to multiple banks, and handles the routing and conversion of messages between Third Party Providers (TPPs) and banks. This will make life easier for TPPs who will only need to implement a single interface and immediately get access to many banks. It could also help banks, as they would not have to directly support onboarding of TPPs (RTS Article 27.6 mandates banks to provide support, for connection and functional testing which could be a costly process if carried out for each individual TPP). This doesn t come free though the meta-aggregators are yet another hungry mouth to feed in an already extended value chain. PSPs need to evaluate the pros and cons of using such an intermediary. Complexity simplified

2 2. APIs, not screen scraping UGLY. Rationale 32 says that screen scraping will no longer be allowed, but something that looks a lot like screen scraping, and which suffers from most of the same security holes, is still allowed. The RTS clearly states that it is optional whether a bank should develop a dedicated interface for the exclusive use of TPPs (generally accepted, but not mandated, to be APIs). The alternative is to allow TPPs to use the same interface offered to and used by the banks customers (e.g. online banking). The latter sounds much like current screen-scraping solutions, but there are conditions. The interface must allow TPPs to identify themselves to the bank (27.1.a), and that identification must take the form of qualified certificates for electronic seals or website authentication (29.1) as defined in the EIDAS regulation 910/2014. A key difference between screen-scraping and other types of interface is whether the user enters their bank-provided security credentials on a bankprovided login, or a TPP-provided page. The RTS allows the latter, as it refers to personalised security credentials and of authentication codes transmitted by or through the TPP (27.3.c). This is bad news from a security point of view, as it is an open invitation to phishing, and introduces a technical break in end-to-end encryption that could be exploited. 3. Payment security up to the banks GOOD. The final RTS has less to say on this topic than the draft. The previous wording said that a PIS would only authenticate the customer (Payment Service User or PSU) in case of a prior contractual agreement between the PIS and the ASPSP, and that agreement would be outside the scope of PSD2. That wording has vanished, and Recital 14 now simply says that PIS Providers have the right to rely on the authentication procedures provided by the bank, and that In such cases, the authentication procedure will remain fully in the sphere of competence of the ASPSP. Having a right is not an obligation, and this implies that there are other cases where authentication does not rely on the ASPSP. Nevertheless, the RTS does not say anywhere that ASPSPs have a right to rely on the authentication procedure provided by a third party, so the onus is still on the ASPSP for authentication. Hence the other cases would require the ASPSP to agree bilaterally with a third party to rely on their credentials. In such cases, the third party would have to adhere to the conditions around SCA and associated credentials laid out in the RTS. Rationale 15 indicates that the payee s PSP has the option not to accept SCA which apparently refers to card acquirers accepting non chip-and-pin transactions, and is discussed further in Comment 2. It clarifies that in such cases, liability always rests with the payee s PSP.

3 4. Authentication codes UGLY. Article 4.1 states that the authentication code is generated based on two or more elements categorised as knowledge, possession and inherence, which is clear. But it goes on to state that The authentication code shall be accepted only once. This is fine for a single payment initiation, but Article 13.1 allows an exemption from SCA for a series of payment transactions with the same amount and the same payee presumably the authorisation code generated for the first payment in the series should be presented for each subsequent payment in the series? Likewise, for account information where an AISP can make up to 4 requests per day (31.5.b) for up to 90 days (10.2.b), presumably the original authorisation code must be presented for all subsequent accesses. Unfortunately, neither of these cases is compatible with the only once provision in 4.1. Article 5.1.c now specifies that any change in amount or payee shall invalidate the authentication code, which is a big improvement on the previous requirement to just change the authentication code, which was impossible to fulfil. It s worth noting that the Dynamic Linking of an authentication code covers the amount and payee, but not specific to the payment reference. So it would be quite possible to obtain an authentication code for a payment with one reference, then use it to execute a payment for the same amount and payee, but for a different reference. This could be abused, for example where the payee is a credit card company and the reference indicates the card account to be paid. The RTS only mentions Dynamic Linking for payment initiation, but it should also be required for consent to a specified set of parameters for AISP access accounts accesses, frequency of access, and so on. It would be best to consider Dynamic Linking as a binding of the payer s consent for transaction(s), be they a single payment, series of payments or an enduring consent to access data. 5. Exemptions from Strong Customer Authentication (SCA) GOOD. This is the area of the RTS that has changed most, and has become more practical. Changes include: For contactless card payments, the single transaction value is raised to 50, and the option to count five consecutive non-sca transactions has been added to provide balance to the previous impractical requirement to just accumulate payment values. A vital exemption is added for unattended transport and parking terminals has helpfully been included, but one should note in the TFL case, that the end amount is not known at the point of contactless exemption as the final billing is often calculated at the end of day based on all travel. No SCA is required for payments to trusted beneficiaries. Comment 79 also clarifies. The exemption for trusted beneficiaries only applies to payment transactions made on an online account by the payer. The PISP cannot create a list of trusted beneficiaries. The low value payment exemption is raised from 10 to 30, with a cumulative value of 100 or a cumulative count of five, aligned to the Contactless exemption. However, the biggest change is described in Article 16, where an exemption is offered subject to Transaction Risk Analysis (TRA). This is discussed further in the following section. In some circumstances there is a bootstrap problem. For example, before applying the whitelist exemption, the ASPSP would need a high level of

4 certainty that the purported payer is indeed who they claim to be. This would require some level of authentication of the payer but that s precisely what the exemption is trying to avoid! 6. Real Time Fraud Detection and Prevention GOOD. Whereas the previous draft mandated real time fraud detection to prevent, detect and block fraudulent payments, the final draft allows for a more nuanced risk analysis approach, with high risk transactions being blocked for suspected fraud, and low risk transactions potentially bypassing SCA. There is also a specific approach with clearer reporting and processing procedures. The final draft introduces exemptions from SCA based on Transaction Risk Analysis. The exemption applies to transactions assessed as low risk, with a value limit depending on the type of transaction (remote card or credit transfer), and the PSP s overall fraud rate, based on a rolling quarterly basis. If the transaction is determined to be low risk, SCA need not be applied by the ASPSP; however as in point 3, it is always their prerogative in the interests of protecting the customer, but would have to be recorded as the TPP may complain about unnecessary friction being added. The list of factors to be considered is quite extensive. Article 2 mandates lists of compromised or stolen authentication elements; the amount of each payment transaction; known fraud scenarios in the provision of payment services; signs of malware infection in any sessions of the authentication procedure. For the SCA exemption to apply, additional factors must be considered including the previous spending patterns of the individual payment service user; the payment transaction history of each of the payment service provider s payment service user; the location of the payer and of the payee at the time of the payment transaction. One interesting point is mentioned in Rationale 24, which says both payees and payers PSPs could trigger such an exemption under their own and exclusive responsibility but with the payer s PSP having the final say. This suggests that the payee s PSP can request SCA exemption (with an assumed liability accepted by the PSP), but the payer s ASPSP can over-ride this and still present the challenge for SCA. This exemption will be critical in delivering a frictionless customer experience, so PSPs that cannot meet the criteria will lose out to those that can. Real time risk assessment is not easy, so expect to see some vigorous competition and innovation in this space and various bi-lateral framework contracts on liability to be developed. 7. Sensitive Payment Data BAD. The final draft still says that ASPSPs must provide AIS with the same information from designated payment accounts and associated payment transactions made available to the payment service user when directly accessing the information, provided that this information does not include display of sensitive payment data. This wording raises a barrier to interoperability, as the information that banks currently make available to users varies widely, and banks may make different decisions about which data is sensitive and therefore must be redacted. Third parties will not be able to rely on a consistent set of data and services across all banks, but will have to adapt on a case by case basis, or settle for the lowest common denominator. Additionally, from our own experience PISPs may need some level of payment account information in the case of credit transfers to help a Payment Service User (PSU) select the correct account, for example based on available balance (as happens today with mobile banking). It is unclear whether ASPSPs can provide this information to PISPs, or whether PISPs must apply as AISPs as well to get the information. In any case, some banks are looking to carry out account selection within their own UI, following the application of SCA. This wouldn t be possible if the payment was exempt

5 from SCA. The lack of clarity in this area raises yet another barrier to interoperability. 8. Use of eidas authorities UGLY. The EBA has put aside its doubts and firmly mandated the use of Digital Certificates (of qualified certificates for electronic seals or website authentication, as the regulation would have it) issued under Regulation 910/2014, aka eidas. Several pieces of data are to be encoded in the certificate, including now a new TPP identifier as used on the register of PSPs in the organisation s home country, and an indicator of the role(s) of the TPP ASPSP, AISP, PISP, PII. There are several practical challenges associated with this decision. Firstly, no process or mechanism is set out in this RTS (or elsewhere) linking the revocation of authorisation of a PSP under Article 13 or precautionary measures under Article 30 to revocation of the Digital Certificate. This means that in principle, ASPSPs must carry out two checks whenever they are presented with a Digital Certificate: the standard OCSP certificate revocation check to the QTSP, and then another check against the home member state competent authority Public Register to ensure they are still authorised, with what role authorisations, and whether the TPP has been given passported authorisation to access services in the ASPSP s home member state. Additionally, the RTS does not set out a standard as to how and where in the Digital Certificate the new additional attributes (Role, Competent Authorities) should be stored. In the absence of a common standard across all member states, it will be a major challenge to extract and interpret the information in the certificate. Again it is left to the industry or a European standardisation initiative to agree this and produce a clear process and structure for Competent Authorities, QTSPs, TPPs and ASPSPs to interoperate securely and seamlessly across the EU. 9. Card Not Present requires Strong Customer Authentication GOOD. Unless a card transaction falls under one of the exemptions, it must go through SCA. This could mean a 3D-Secure type process, but using two factors instead of the double knowledge factor(s) (e.g. Password + Date of Birth) being used by most banks currently. Vendors have rushed out solutions such as Dynamic CVV, where the CVV on the card changes regularly. Using this as one of the SCA components proves Possession, which along with Knowledge satisfies the two factor requirement. The main exemption that might apply would be the Transaction Risk Analysis (TRA), which could potentially bypass SCA for companies whose transactions are mainly below the applicable TRA limit ( 100, 250 or 500 depending on the PSP s historical fraud rate). 3-D Secure 2.0 should be able to meet these requirements. As well as browser-based payments, it will also support in-app, mobile, and digital wallet payments. It will support token-based and biometric authentication instead of static passwords, and will carry additional data such as device profile to support risk-based decisions and allow possible TRA-based bypass of SCA.

6 10. Trusted Execution Environments for Multi-Purpose Devices BAD. This section deals with the security of mobile phones and similar devices. It seems like the EBA has caved into pressure from the industry lobbying and has now taken a retrograde step. Instead of the well-defined term Trusted Execution Environment it is using the term Secure Execution Environment which has no current industry definition and allows any vendor to claim compliance. From our knowledge, there are still effectively only three ways to provide for 2FA possession element on a multi-purpose device: 1. Trusted Execution Environment the gold standard for security and convenience, however many phones will not be enabled for this. Also, Apple aren t the most open of providers when it comes to their phones. 2. IMEI/USIM/ICCID/IMSI combination which will cover all other non-tee enabled phones. Put simply, if you could hack the ICCID today, we d all be making free calls and data. This method has definitely proven robust in the real world. 3. Whitebox Crypto in an App this is the least desirable and lacks sufficient market exposure to provide confidence. Also susceptible to OS issues, malware and other software based attack that the previous two options would not have. An ASPSP would also have to ensure that the PSU was keeping the relevant software(s) and OS on their phone updated, much in the way we re always being pushed to download Rapport/Trusteer on the web, but invitations to download software can actually be vectors for malware infection. Given the EBA s difficuly in clearly defining an acceptable standard in this area, it will be interesting to see how ASPSP security officers deal with this in the coming years. In the meantime it s a case of buyer beware. From theory to practice It s one thing to discuss the RTS, but how will it work in the real world? Icon Solutions have put together a demonstration of how merchants, PISPs and ASPSPs can interact using web screens, APIs and back office systems to support e-commerce according to the final RTS. If you would like to see the demonstration for yourself, please contact Icon using the details below and we will be delighted to arrange a convenient time. If you would like to learn more about how Icon help your organisation with any specific PSD2 or payment challenges, please contact; Tom Hay, Head of Payments at Icon Solutions tom.hay@iconsolutions.com, uk.linkedin.com/in/tomhay To find out more iconsolutions.com PSD2@iconsolutions.com

COMMISSION DELEGATED REGULATION (EU) No /.. of XXX

COMMISSION DELEGATED REGULATION (EU) No /.. of XXX EUROPEAN COMMISSION Brussels, XXX [ ](2017) XXX draft COMMISSION DELEGATED REGULATION (EU) No /.. of XXX supplementing Directive 2015/2366 of the European Parliament and of the Council with regard to regulatory

More information

Opinion of the European Banking Authority on the implementation of the

Opinion of the European Banking Authority on the implementation of the EBA-Op-2018-04 13 June 2018 Opinion of the European Banking Authority on the implementation of the RTS on SCA and CSC Introduction and legal basis 1. The competence of the European Banking Authority (EBA)

More information

DRAFT DELEGATED REGULATION ON STRONG CUSTOMER AUTHENTICATION AND SECURE COMMUNICATION

DRAFT DELEGATED REGULATION ON STRONG CUSTOMER AUTHENTICATION AND SECURE COMMUNICATION The Consumer Voice in Europe DRAFT DELEGATED REGULATION ON STRONG CUSTOMER AUTHENTICATION AND SECURE COMMUNICATION BEUC response to EBA consultation 12/10/2016 Contact: Farid Aliyev - Jean Allix Financialservices@beuc.eu

More information

PSD2 - Second Payment Services Directive. Information Set

PSD2 - Second Payment Services Directive. Information Set PSD2 - Second Payment Services Directive Information Set PSD2: at the starting line February 2017 EBA published the final draft RTS on SCA November 2017 EC published the final RTS on SCA January 13 2018

More information

RESPONSES TO CONSULTATION PAPER

RESPONSES TO CONSULTATION PAPER RESPONSES TO CONSULTATION PAPER re: for: Consultation Paper on the draft Regulatory Technical Standards specifying the requirements on strong customer authentication and common and secure communication

More information

PSD2 IMPLICATIONS OF THE REGULATION August 8, Regina Lau, Chief Strategy Officer, Ingenico epayments Zainab Mir, Counsel Payments, Netflix

PSD2 IMPLICATIONS OF THE REGULATION August 8, Regina Lau, Chief Strategy Officer, Ingenico epayments Zainab Mir, Counsel Payments, Netflix PSD2 IMPLICATIONS OF THE REGULATION August 8, 2017 Regina Lau, Chief Strategy Officer, Ingenico epayments Zainab Mir, Counsel Payments, Netflix OVERVIEW 1. PSD2 Overview Regina Lau 2. Strong Customer Authentication

More information

Trending: How does PSD2 trigger innovation?

Trending: How does PSD2 trigger innovation? Trending: How does PSD2 trigger innovation? Speakers: Nils Jung, Managing Partner, Innopay Germany Hakan Eroglu, Senior Manager Digitization in Payments & Banking, Accenture Trending: How does PSD2 trigger

More information

Euro Retail Payments Board (ERPB) Final Report of the ERPB Working Group on Payment Initiation Services. ERPB Meeting 29 November 2017

Euro Retail Payments Board (ERPB) Final Report of the ERPB Working Group on Payment Initiation Services. ERPB Meeting 29 November 2017 ERPB/2017/012 ERPB PIS 034-17 Version 1.0 15 November 2017 Euro Retail Payments Board (ERPB) Final Report of the ERPB Working Group on Payment Initiation Services ERPB Meeting 29 November 2017 ERPB PIS

More information

Dirk Haubrich, Nilixa Devlukia. Public Hearing, EBA, London, 25 July 2018

Dirk Haubrich, Nilixa Devlukia. Public Hearing, EBA, London, 25 July 2018 Draft Guidelines on the conditions to be met to benefit from an exemption from contingency measures under Article 33(6) of Regulation (EU) 2018/389 (RTS on SCA & CSC under PSD2) Dirk Haubrich, Nilixa Devlukia

More information

SecuRe Pay recommendations for the security of mobile payments

SecuRe Pay recommendations for the security of mobile payments ECB-PUBLIC FINAL SecuRe Pay recommendations for the security of mobile payments Stephanie Czák Senior Market Infrastructure Expert European Central Bank ETSI/EC Collaborative Ecosystem for M-Payments Workshop

More information

The Second Payment Services Directive: Scoping out the impacts of the Regulatory Technical Standards

The Second Payment Services Directive: Scoping out the impacts of the Regulatory Technical Standards The Second Payment Services Directive: Scoping out the impacts of the Regulatory Technical Standards TABLE OF CONTENTS INTRODUCTION: A CRITICAL MOMENT FOR PSD2 KEY ASPECTS OF THE FINAL DRAFT RTS IMPACTS

More information

DEFINING NEW CUSTOMER JOURNEYS

DEFINING NEW CUSTOMER JOURNEYS DEFINING NEW CUSTOMER JOURNEYS Payment Services Directive 2 (PSD2) Scoping out the impacts of the Regulatory Technical Standards (RTS) on Strong Customer Authentication and Common and Secure Open Standards

More information

Challenges and solutions. related to Digital Transformation Training & workshop

Challenges and solutions. related to Digital Transformation Training & workshop Challenges and solutions related to Digital Transformation Training & workshop Agenda 09:00-09:30 Registration, coffee 09:30 11:00 Trends in digitalization Regulatory challenges (PSD2 & other) Business

More information

UK Finance welcome the clarity the EBA is giving on availability and performance of dedicated interfaces.

UK Finance welcome the clarity the EBA is giving on availability and performance of dedicated interfaces. UK Finance response to EBA consultation on draft Guidelines on the conditions to be met to benefit from an exemption from contingency measures under Article 33(6) of Regulation (EU) 2018/389 (RTS on SCA

More information

Strong Customer Authentication in Practice

Strong Customer Authentication in Practice Strong Customer Authentication in Practice A Signicat whitepaper June 2017 1 This white paper has been produced on behalf of Signicat by Norfico (www.norfico.net) and Consult Hyperion (www.chyp.com) Table

More information

Turning the Revised Payment Services Directive into Digital Opportunity

Turning the Revised Payment Services Directive into Digital Opportunity Turning the Revised Payment Services Directive into Digital Opportunity Contents 1. Introduction 3 2. The Business Risk PSD2 Presents 4 3. The Opportunity for Value Creation 6 4. Making it Happen 7 2 Turning

More information

Guidelines for PSD2 Implementation

Guidelines for PSD2 Implementation nextdigitalbanking.com Guidelines for PSD2 Implementation Helping banks explore API strategies and options CONTENTS: Shifting mindsets and expectations Top five strategic considerations for PSD2 implementation

More information

Open Banking PSD2, GDPR and the American Merchant

Open Banking PSD2, GDPR and the American Merchant Your source for payments education Open Banking PSD2, GDPR and the American Merchant Scott Adams Evolutioneer FraudPVP Rene Pelegero President & Managing Director Retail Payments Global Consulting Group

More information

Quali-Sign Banking. An example of how to meet the PSD2 segregation requirements. Michael Adams 3 rd November Quali-Sign Ltd

Quali-Sign Banking. An example of how to meet the PSD2 segregation requirements. Michael Adams 3 rd November Quali-Sign Ltd Quali-Sign Banking Quali-Sign Ltd An example of how to meet the PSD2 segregation requirements. Michael Adams 3 rd November 2016 2016 Quali-Sign Ltd michael_adams@quali-sign.com Context The PSD2 segregation

More information

PSD2 is on top of our agenda

PSD2 is on top of our agenda PSD2 is on top of our agenda Stating the obvious There is no do nothing option for payment service providers Even basic PSD2 compliance requires strategic choices There is a highway of opportunities The

More information

The Payment Services Directive 2 Background and Content

The Payment Services Directive 2 Background and Content The Payment Services Directive 2 Background and Content The Jon Bing Memorial Seminar 2017 27 April 2017 Siv Bergit Pedersen Legal counsel MNBA DNB Bank ASA Background Norway Financial Agreements Act (Finansavtaleloven)

More information

API Banking. The shift to open banking

API Banking. The shift to open banking API Banking The shift to open banking The shift to open banking and move towards value added services. as the platform for compliance and beyond Open banking is set to have a major impact on the financial

More information

FINAL REPORT ON THE DRAFT RTS AND ITS ON THE EBA REGISTER UNDER THE PSD2 EBA/RTS/2017/10 EBA/ITS/2017/ December 2017.

FINAL REPORT ON THE DRAFT RTS AND ITS ON THE EBA REGISTER UNDER THE PSD2 EBA/RTS/2017/10 EBA/ITS/2017/ December 2017. EBA/RTS/2017/10 EBA/ITS/2017/07 13 December 2017 Final Report on Draft Regulatory Technical Standards setting technical requirements on development, operation and maintenance of the electronic central

More information

EMV Secure Remote Commerce. Frequently Asked Questions (FAQ)

EMV Secure Remote Commerce. Frequently Asked Questions (FAQ) EMV Secure Remote Commerce Frequently Asked Questions (FAQ) 1. What is EMV * Secure Remote Commerce? EMV Secure Remote Commerce (SRC) offers an approach to promote security and interoperability within

More information

THE PAYMENT SERVICES DIRECTIVE II (PSD II) Liberalisation of electronic payment transactions

THE PAYMENT SERVICES DIRECTIVE II (PSD II) Liberalisation of electronic payment transactions April 2017 THE PAYMENT SERVICES DIRECTIVE II (PSD II) Liberalisation of electronic payment transactions Hurry up! Only a few more months until January 2018, when payment service providers are obliged to

More information

Aktualitātes no Berlin Group NextGen PSD2 konferences. Māris Ozoliņš

Aktualitātes no Berlin Group NextGen PSD2 konferences. Māris Ozoliņš Aktualitātes no Berlin Group NextGen PSD2 konferences. Māris Ozoliņš Rīga, 2017. gada 15. novembris THE Berlin GROUP A EUROPEAN STANDARDS INITIATIVE ««««««««««««««««««««««««NextGenPSD2 Conference 2017

More information

The communication between Third Party Providers and Banks. PSD2 in a nutshell

The communication between Third Party Providers and Banks. PSD2 in a nutshell www.pwc.com/psd2 The communication between Third Party Providers and Banks. What will the impact of technology be? PSD2 in a nutshell Summary The banking system is at a turning point, under the pressure

More information

The revised Payment Services Directive (PSD2)

The revised Payment Services Directive (PSD2) Regulatory agenda updates The revised Payment Services Directive (PSD2) What you need to know Revised Payment Services Directive (PSD2) to increase scope, obligations, and to offer business opportunities

More information

PSD2 AND SECURITY ISSUES

PSD2 AND SECURITY ISSUES MEMO N 08 18, RUE LA FAYETTE 75440 PARIS CEDEX 09 FRANCE TEL. : +33 (0)1 48 00 52 52 PSD2 AND SECURITY ISSUES FBF.FR/EN/HOME Draft completed 2017 ? 01 WHAT IS PSD2? What is PSD2? What issues does it raise

More information

The communication between Third Party Providers and Banks. PSD2 in a nutshell

The communication between Third Party Providers and Banks. PSD2 in a nutshell www.pwc.ch The communication between Third Party Providers and Banks. What will the impact of technology be? PSD2 in a nutshell Summary The banking system is at a turning point, under the pressure of the

More information

PSD2 open banking for Prepaid Programme Managers. Implications and Requirements

PSD2 open banking for Prepaid Programme Managers. Implications and Requirements A RegTech Company PSD2 open banking for Prepaid Programme Managers Implications and Requirements White Paper September 2018 1 Regulatory challenge in the EU In January 2018 the European Union Payment Services

More information

PSD2 TAS Open Banking

PSD2 TAS Open Banking PSD2 A challenge for Banks but a huge opportunity at the same time for new services TAS Group 2017 Some highlights on PSD2 driven changes PSD2 introduces a new legal structure to payments in the EU, challenging

More information

WHITE PAPER. Encouraging innovation in payments through the PSD2 initiative. Abstract

WHITE PAPER. Encouraging innovation in payments through the PSD2 initiative. Abstract WHITE PAPER Encouraging innovation in payments through the PSD2 initiative Abstract Revised Directive on Payment Services (PSD2) is primarily aimed at bringing new, online modes of payments initiation

More information

PSD2 open banking for E-Money Issuers. Implications and Requirements

PSD2 open banking for E-Money Issuers. Implications and Requirements A RegTech Company PSD2 open banking for E-Money Issuers Implications and Requirements Webinar November 2018 1 David Parker, Advisor & co-founder Konsentus Please ask questions as we go along 2 Regulatory

More information

Challenges and solutions

Challenges and solutions Challenges and solutions related to the entry into force of the RTS SCA on the 14 September 2019 Introduction The PSD2 and the so-called open banking are two of the most frequently discussed topics in

More information

ECSG (Vol Ref. 8.A01.00) SEPA CARDS STANDARDISATION (SCS) VOLUME. Payments and Cash Withdrawals with Cards in SEPA

ECSG (Vol Ref. 8.A01.00) SEPA CARDS STANDARDISATION (SCS) VOLUME. Payments and Cash Withdrawals with Cards in SEPA ECSG001-17 01.03.2017 (Vol Ref. 8.A01.00) SEPA CARDS STANDARDISATION (SCS) VOLUME STANDARDS REQUIREMENTS ANNEX 01 SEPA CARDS TRANSACTION FLOWS Payments and Cash Withdrawals with Cards in SEPA Applicable

More information

Consultation Paper. Draft Regulatory Technical Standards

Consultation Paper. Draft Regulatory Technical Standards EBA/CP/2017/09 29 June 2017 Consultation Paper Draft Regulatory Technical Standards on the criteria for determining the circumstances in which the appointment of a central contact point pursuant to Article

More information

BEUC RESPONSE TO EUROPEAN BANKING AUTHORITY DISCUSSION PAPER

BEUC RESPONSE TO EUROPEAN BANKING AUTHORITY DISCUSSION PAPER The Consumer Voice in Europe BEUC RESPONSE TO EUROPEAN BANKING AUTHORITY DISCUSSION PAPER on future draft Regulatory Technical Standards on strong customer authentication and secure communication under

More information

Helping ASPSPs implement PSD2 and take advantage of Open Banking January 2019

Helping ASPSPs implement PSD2 and take advantage of Open Banking January 2019 Helping ASPSPs implement PSD2 and take advantage of Open Banking January 2019 Version 1.36 1 We make it easier for ASPSPs to implement PSD2 and take advantage of Open Banking We have developed a comprehensive

More information

Market environment and implementation timeline PSD2 in a nutshell

Market environment and implementation timeline PSD2 in a nutshell www.pwc.ch Market environment and implementation timeline PSD2 in a nutshell Why do we need a new Payment Services Directive (PSD)? By 13 th January 2018, Member States will have to implement the Directive

More information

PAYMENT SERVICES DIRECTIVE 2 WHAT IS ALL THE FUSS ABOUT ANYWAY?

PAYMENT SERVICES DIRECTIVE 2 WHAT IS ALL THE FUSS ABOUT ANYWAY? PAYMENT SERVICES DIRECTIVE 2 WHAT IS ALL THE FUSS ABOUT ANYWAY? An extract from the Scandinavian financial services newsletter Winter 2016 Newsletter 2 SCANDINAVIAN FINANCIAL SERVICES 2016 WINTER EDITION

More information

PRETA and PSD2. Access to Accounts (XS2A) PRETA All rights reserved. PRETA All rights reserved.

PRETA and PSD2. Access to Accounts (XS2A) PRETA All rights reserved. PRETA All rights reserved. PRETA and PSD2 Access to Accounts (XS2A) Aims of PSD2 Access to Account PSD2 State of play PSD2 was published in EU's OJ on 23 December 2015; PSD2 comes into force 2 years later, i.e. 13 January 2018 Subject

More information

The Future of Payment Security in Canada

The Future of Payment Security in Canada The Future of Payment Security in Canada October 2017 1 Visa Canada Public The Future of Payment Security in Canada Notices Forward-Looking Statements This presentation contains forward-looking statements

More information

117 shades of black within PSD2

117 shades of black within PSD2 117 shades of black within PSD2 Thoughts on PSD2 implementation from strategic and technical perspective. Preface Last 2+ years has brought a lot of changes within payment industry. It all started on October

More information

The Open Banking PSD2 Implementation Strategies

The Open Banking PSD2 Implementation Strategies The Open Banking PSD2 Implementation Strategies How to meet the challenge of Open Banking Introduction Open Banking is the next step in a technology evolution driven by the API economy. Technology giants

More information

Implementation of the revised Payment Services Directive (PSD2): draft Approach Document and draft Handbook changes

Implementation of the revised Payment Services Directive (PSD2): draft Approach Document and draft Handbook changes Implementation of the revised Payment Services Directive (PSD2): draft Approach Document and draft Handbook changes The Building Societies Association response to FCA CP17/11 Restricted 8 June 2017 Introduction

More information

Opening Keynote. Digital payments in the context of the evolving financial market infrastructure in the euro area

Opening Keynote. Digital payments in the context of the evolving financial market infrastructure in the euro area Opening Keynote Digital payments in the context of the evolving financial market infrastructure in the euro area Marc Bayle de Jessé, Director General Market Infrastructure and Payments, ECB, Conference

More information

Trusted KYC Data Sharing Standards Scope and Governance Oversight

Trusted KYC Data Sharing Standards Scope and Governance Oversight November 2017 Trusted KYC Data Sharing Standards Scope and Governance Oversight Handover Document Contents Preface... 3 Overview... 5 1 Sharing Capabilities and Interoperability... 7 1.1 Data Sharing Behaviour

More information

EMBEDDING THE PAYMENTS PROCESS: 3 STEPS FOR INTEGRATION AN EBOOK BY

EMBEDDING THE PAYMENTS PROCESS: 3 STEPS FOR INTEGRATION AN EBOOK BY EMBEDDING THE PAYMENTS PROCESS: 3 STEPS FOR INTEGRATION AN EBOOK BY TABLE OF CONTENTS Intended Audience... 3 Introduction... 4 Step 1: Choose an Onboarding Method... 10 Step 2: Determine Transaction Processing

More information

Market environment and implementation timeline PSD2 in a nutshell

Market environment and implementation timeline PSD2 in a nutshell www.pwc.com/psd2 Market environment and implementation timeline PSD2 in a nutshell Why do we need a new Payment Services Directive (PSD)? By 13 th January 2018, Member States will have to implement the

More information

Input to Members of the European Parliament on the PSD2 RTS proposal covering banks obligations

Input to Members of the European Parliament on the PSD2 RTS proposal covering banks obligations Input to Members of the European Parliament on the PSD2 RTS proposal covering banks obligations ESBG (European Savings and Retail Banking Group) Rue Marie-Thérèse, 11 - B-1000 Brussels ESBG Transparency

More information

Review of Priviti PSD2 Use Case and its positioning compared to alternative marketplace offerings

Review of Priviti PSD2 Use Case and its positioning compared to alternative marketplace offerings Review of Priviti PSD2 Use Case and its positioning compared to alternative marketplace offerings The revised Payment Service Directive (PDS2) is a directive focused on better integration of an internal

More information

OBP at the heart of your PSD2 strategy

OBP at the heart of your PSD2 strategy OBP at the heart of your PSD2 strategy API Days Nov 2017 Simon Redfern Open Banking Open APIs for every bank.! Open Standards! Open Source! Open Data! Open Innovation! Why do we need a Web site?! Of course

More information

The EU Regulations on payments

The EU Regulations on payments The EU Regulations on payments Impacts - Options - Customer ownership Prepaid Summit Europe VISA Timetric - Milano - 2016.10.27 E- Payment & SEPA Adviser 2010 Colt Telecom Group Limited. All rights reserved.

More information

EMV 3-D Secure Press Kit Q&A

EMV 3-D Secure Press Kit Q&A EMV 3-D Secure Press Kit Q&A 1. What is EMV 3-D Secure? EMV 3-D Secure (3DS) is a messaging protocol that promotes frictionless consumer authentication and enables consumers to authenticate themselves

More information

NextGen PSD2. A European Standard for PSD2 XS2A

NextGen PSD2. A European Standard for PSD2 XS2A NextGen PSD2 A European Standard for PSD2 XS2A Berlin Group and NextGenPSD2 The NextGenPSD2 Initiative is a dedicated Task Force of the Berlin Group with the goal to create an open, common and harmonised

More information

Ensuring the Safety & Security of Payments. Faster Payments Symposium August 4, 2015

Ensuring the Safety & Security of Payments. Faster Payments Symposium August 4, 2015 Ensuring the Safety & Security of Payments Faster Payments Symposium August 4, 2015 Problem Statement: The proliferation of live consumer account credentials Bank issues physical card Plastic at point

More information

PSD2 Antoine Larmanjat

PSD2 Antoine Larmanjat PSD2 Antoine Larmanjat Brussels May 2017 Card Issuers Winners and Losers of PSD2 PISPs AISPs Card schemes Retailers Card Issuing PSPs Fintechs PSPs Banks Clearing Houses Consumers 2 AISPs New Business

More information

EBA/RTS/2017/ December Final Report. Draft regulatory technical standards. on central contact points under Directive (EU) 2015/2366 (PSD2)

EBA/RTS/2017/ December Final Report. Draft regulatory technical standards. on central contact points under Directive (EU) 2015/2366 (PSD2) EBA/RTS/2017/09 11 December 2017 Final Report Draft regulatory technical standards on central contact points under Directive (EU) 2015/2366 (PSD2) FINAL REPORT ON CENTRAL CONTACT POINTS UNDER THE PSD2

More information

PSD2 and Open Banking Summary of the most important lessons learned from the PSD2 workshop of June 22, 2018

PSD2 and Open Banking Summary of the most important lessons learned from the PSD2 workshop of June 22, 2018 PSD2 and Open Banking Summary of the most important lessons learned from the PSD2 workshop of June 22, 2018 On June 22, 2018, ICT Solutions Ltd. and Online Business Technologies held a joint international

More information

Crash Course: What are EMV and the EMV Liability Shift?

Crash Course: What are EMV and the EMV Liability Shift? Are You EMV Ready? Are You EMV Ready? In the months leading up to October, 2015, the EMV liability shift and the details surrounding it have been the talk of the retail and hospitality industries. A significant

More information

NextGen PSD2. A European Standard for PSD2 XS2A

NextGen PSD2. A European Standard for PSD2 XS2A NextGen PSD2 A European Standard for PSD2 XS2A Berlin Group NextGenPSD2 The NextGenPSD2 Initiative is a dedicated Task Force of the Berlin Group with the goal to create an open, common and harmonised European

More information

ERPB REACTION TO THE EUROPEAN COMMISSION S GREEN PAPER ON RETAIL FINANCIAL SERVICES

ERPB REACTION TO THE EUROPEAN COMMISSION S GREEN PAPER ON RETAIL FINANCIAL SERVICES ERPB/2016/001 ERPB REACTION TO THE EUROPEAN COMMISSION S GREEN PAPER ON RETAIL FINANCIAL SERVICES 1. Introduction The Euro Retail Payments Board (ERPB) supports the European Commission s decision to launch

More information

Andreas Strobel SPA Board Member shaping the future of payment technology

Andreas Strobel SPA Board Member shaping the future of payment technology A Secure Profile for Tokenization in E and M-Commerce Andreas Strobel SPA Board Member Who we are The Smart Payment Association addresses the challenges of today s evolving payment ecosystem. We offer

More information

DATE: 17/11/2017 Open Banking

DATE: 17/11/2017 Open Banking DATE: 17/11/2017 Open Banking FAO CMA: Proposed amendments to the Agreed Arrangements Adam Land Senior Director of Remedies, Business and Financial Analysis Competition and Markets Authority Victoria House

More information

Is there a case for the regulation of Tokenization services?

Is there a case for the regulation of Tokenization services? Is there a case for the regulation of Tokenization services? An SPA Position May 2016 1. Introduction The initiation of a card payment first requires the transmission of the card s Payment Account Number

More information

PSD2 & Instant Payment

PSD2 & Instant Payment PSD2 & Instant Payment Presentation to Investors June 2017 Agenda Introduction PSD2/Instant Payment Impacts for Banks Worldline offering for Banks PSD2/Instant Payment Impacts for Merchants Worldline offering

More information

Legal Aspects of Identity Management

Legal Aspects of Identity Management Legal Aspects of Identity Management Luca Castellani Secretary, Working Group IV (Electronic Commerce) Traditional approach to identity management Need to identify physical persons to establish trust,

More information

Industry Briefing Strong authentication of Internet Payments in Europe - the new PSD2

Industry Briefing Strong authentication of Internet Payments in Europe - the new PSD2 Industry Briefing Strong authentication of Internet Payments in Europe - the new PSD2 Copyright 2015 VASCO Data Security. All rights reserved. No part of this publication may be reproduced, stored in a

More information

Visa s Future of Security Roadmap: Australia

Visa s Future of Security Roadmap: Australia Visa s Future of Security : Australia Contents Executive Summary 3-Domain Secure 2.0 Biometrics Tokenisation EMV Chip Technology Expanding Mobile Acceptance Mobile Geo-location Transaction Controls and

More information

Procedural Guidelines RuPay QR code

Procedural Guidelines RuPay QR code Procedural Guidelines RuPay QR code Version 1.0 Version 1.0 Page 1 of 8 Amendment History Sr. Version number Summary of Change Change Month & Year 1 1.0 Initial Version Feb 2017 2 3 Version 1.0 Page 1

More information

PSD2: An Open Banking Catalyst

PSD2: An Open Banking Catalyst PSD2: An Open Banking Catalyst Leverage Open APIs to unlock new business opportunities It is short-sighted to treat the European Union s second Payment Services Directive (PSD2) and other European regulations

More information

EMV 3-D Secure Press Kit Q&A

EMV 3-D Secure Press Kit Q&A EMV 3-D Secure Press Kit Q&A 1. What is EMV 3-D Secure? EMV Three-Domain Secure (3DS) is a messaging protocol that enables frictionless consumer authentication and the ability for consumers to authenticate

More information

Payment Services Directive 2 and other European Laws on Payments Systems Ayse Zoodsma-Sungur

Payment Services Directive 2 and other European Laws on Payments Systems Ayse Zoodsma-Sungur Payment Services Directive 2 and other European Laws on Payments Systems Ayse Zoodsma-Sungur Seventh Conference on Payment and Securities Settlement Systems, Ohrid 7-10 July 2014 Outline Regulation, yes

More information

Unleashing the API Economy for Banking Payment Services Directive 2 (PSD2)

Unleashing the API Economy for Banking Payment Services Directive 2 (PSD2) IBM BusinessConnect A new era of thinking Unleashing the API Economy for Banking Payment Services Directive 2 (PSD2) Richard Gamblin Digital Transformation Architect European Technical Leader richard.gamblin@uk.ibm.com

More information

Top business challenges imposed by the market s shift towards Open Banking. Technological foundation for your new service offering

Top business challenges imposed by the market s shift towards Open Banking. Technological foundation for your new service offering WHAT IS IT ABOUT This white paper describes challenges and strategies of banks, merchants and other financial institutions who serve consumers within the PSD2 payment ecosystem. 2 ❶ Top business challenges

More information

Technology Innovation Exchange 2017

Technology Innovation Exchange 2017 1 2 3 Significant period of change in the next 9 months Between PSD2, OBWG and CMA alone, there is significant, directionally aligned, activity aimed at transforming the landscape. The timing and degree

More information

Citi Pay App Frequently Asked Questions

Citi Pay App Frequently Asked Questions Citi Pay App Frequently Asked Questions 1. What is Citi Pay? Citi Pay provides the convenience of making secure, in-store payments using your compatible Android mobile phone. This is an optional feature

More information

Nordea webinar 29/ : PSD2 Access to Accounts a game changer

Nordea webinar 29/ : PSD2 Access to Accounts a game changer Nordea webinar 29/11-2017: PSD2 Access to Accounts a game changer Brief intro setting the scene Some practicalities: 9.00-9.45 CET Webinar is being recorded - material will be uploaded to www.nordea.com/vendors

More information

Safeguarding Online Transactions, Reducing Fraud and Improving the Consumer Experience

Safeguarding Online Transactions, Reducing Fraud and Improving the Consumer Experience Safeguarding Online Transactions, Reducing Fraud and Improving the Consumer Experience Gustavo Kok, Dafiti Group Frederico Trevisan, Santander Dennis Gamiello, Mastercard Introduction - Authentication

More information

How PSD2 impacts marketplaces and platforms

How PSD2 impacts marketplaces and platforms How PSD2 impacts marketplaces and platforms A Stripe guide for navigating the European regulatory changes By Michael Cocoman & David Schreiber The new European payments law, known as the second Payment

More information

Mobile and Contactless Payments Requirements and Interactions

Mobile and Contactless Payments Requirements and Interactions Mobile and Contactless Payments Requirements and Interactions Version 1.0 Date: February 2018 2018 U.S. Payments Forum and Smart Card Alliance. All rights reserved. Page 1 About the U.S. Payments Forum

More information

Navigating the components of Open Banking

Navigating the components of Open Banking White Paper Navigating the components of Open Banking How to create a suitable architecture Creating value from your infrastructure Open Banking will bring new challenges for lenders - their technology

More information

1. General comments on EBA s reasoning

1. General comments on EBA s reasoning The Future of European Fintech Alliance Commenting on EBA s opinion on the European Commission s amendments to the RTS on authentication and communication under PSD2 Introduction The Future of European

More information

Combating Fraud and Data Breaches

Combating Fraud and Data Breaches Combating Fraud and Data Breaches End-to-end strategic management insights Overview In 2014, the number of data breaches increased nearly 28%, according to the Identity Theft Research Center (IRTC). The

More information

Shaping the future of payments

Shaping the future of payments Helmut Wacket Head of Market Integration Division Shaping the future of payments QED Brussels, 29 March 2017 Changes in the retail payments landscape Classical payment instruments innovative payment solutions

More information

Work stream 3 Implementation Plan Industry Landscape

Work stream 3 Implementation Plan Industry Landscape DRAFT Work stream 3 Implementation Plan Industry Landscape Payments Strategy Forum April 2017 Payments Industry Landscape NPA Implementation The purpose of this document is to provide a view of the change

More information

Why Authentication Matters

Why Authentication Matters Why Authentication Matters What you will learn today The challenges facing our industry The opportunities to adapt and improve How increasing mandates, requirements and regulations are impacting commerce

More information

Research supported by. Whitepaper. Omni-Channel Authentication: A Unified Approach to a Multi-Authenticator World

Research supported by. Whitepaper. Omni-Channel Authentication: A Unified Approach to a Multi-Authenticator World Research supported by Whitepaper Omni-Channel Authentication: A Unified Approach to a Multi-Authenticator World Table of Contents 4 5 6 7 8 10 13 15 16 17 19 20 21 Overview Why an Omni-Channel Authentication

More information

Payment Services Directive 2: What it Means for Banks, Customers, and Payment Service Providers

Payment Services Directive 2: What it Means for Banks, Customers, and Payment Service Providers Payment Services Directive 2: What it Means for Banks, Customers, and Payment Service Providers Abstract The Payment Services Directive 2 (PSD2) can have a significant impact on customers, banks, and payment

More information

Sage Payment Solutions. Reduce your PCI liability with integrated payment solutions

Sage Payment Solutions. Reduce your PCI liability with integrated payment solutions Sage Payment Solutions Reduce your PCI liability with integrated payment 1 Emerging Payment Card Industry (PCI) standards have turned up the heat on companies that deliver involving payment processing.

More information

On the Way to a Europe-wide FinTech Regulatory Sandbox?

On the Way to a Europe-wide FinTech Regulatory Sandbox? Europe-wide FinTech briefing The European Banking Federation ( EBF ) recently issued a paper recommending the creation of a sandbox, which would let companies experiment with new cross-border financial

More information

Edgar, Dunn & Company A Closer Look at the Payment Regulations. Webinar 25 th June 2015

Edgar, Dunn & Company A Closer Look at the Payment Regulations. Webinar 25 th June 2015 Edgar, Dunn & Company A Closer Look at the Payment Regulations Webinar 25 th June 2015 Edgar, Dunn & Company, 2015 Introduction This webinar will focus on two key regulatory topics: Multilateral Interchange

More information

Stock Taking Exercise & Implementation plan Progress Report

Stock Taking Exercise & Implementation plan Progress Report www.cardscsg.eu Click to edit Master title style Pres CSG 032-14 SEPA Card Standardisation Stock Taking Exercise & Implementation plan Progress Report ERPB - 1 December 2014 What is the CSG? The Cards

More information

Big Data, Security and Privacy: The EHR Vendor View

Big Data, Security and Privacy: The EHR Vendor View Taking a step towards Big Data, Security and Privacy: proactive health + care The EHR Vendor View Bob Harmon, MD Physician Executive, Cerner Corporation Presented to Preventive Medicine 2016 Washington,

More information

Guiding Principles for Next Generation Mobile Payments NFC Solutions Summit 2012

Guiding Principles for Next Generation Mobile Payments NFC Solutions Summit 2012 Guiding Principles for Next Generation Mobile Payments NFC Solutions Summit 2012 Marianne Crowe Vice President, Payment Strategies Federal Reserve Bank of Boston May 23, 2012 Federal Reserve Perspective

More information

The changing regulation around mobile payments

The changing regulation around mobile payments 1 The changing regulation around mobile payments 28/09/2016 Financial Services analysis: With approximately 93% of adults owning or using a mobile phone in the UK and the introduction of tokenisation services

More information

WHO S GOT IT? WHO GETS IT?

WHO S GOT IT? WHO GETS IT? 3D SECURE 2.0: WHO S GOT IT? WHO GETS IT? An Outlook on Merchant Adoption BUSINESS-DRIVEN SECURITY SOLUTIONS 3D SECURE AUTHENTICATION 2.0: MERCHANTS WHO GOT IT ARE GETTING IT Online merchants whose experience

More information

Current Version: June 9, 2017 DIGITAL WALLET AGREEMENT. This Agreement is between you and Coast Capital Savings Credit Union ( CCS ).

Current Version: June 9, 2017 DIGITAL WALLET AGREEMENT. This Agreement is between you and Coast Capital Savings Credit Union ( CCS ). Current Version: June 9, 2017 DIGITAL WALLET AGREEMENT This Agreement is between you and Coast Capital Savings Credit Union ( CCS ). Your use of any eligible third party mobile payment or digital wallet

More information

A Guide to Evaluating Salesforce AppExchange Apps

A Guide to Evaluating Salesforce AppExchange Apps A Guide to Evaluating Salesforce AppExchange Apps There are thousands of apps available today on the Salesforce AppExchange. This paper will help you assess security, speed and scalability differences

More information